IIS 4.0 and Site Server 3.0 Exposure via Improper Virtual Directory Naming
CVE-2000-0025
Currently unrated
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 21 December 1999
Summary
IIS 4.0 and Site Server 3.0 are susceptible to a vulnerability that allows remote attackers to access the source code of ASP files unintentionally. This exposure occurs when an ASP file resides in a virtual directory with a name that contains certain extensions, such as .com, .exe, .sh, .cgi, or .dll. As a result, this misconfiguration can lead to unauthorized disclosure of sensitive information, enabling attackers to exploit the exposed source code.
References
EPSS Score
46% chance of being exploited in the next 30 days.
Timeline
Vulnerability Reserved
Vulnerability published